TCShell 1.0
(Trojan.Win32.Small.hk)

by Turbo_Compiler

Written in Microsoft Visual C++, compressed with FSG

Released in February 2004

more versions


Server:
dropped files:
c:\WINDOWS\system32\Tc.dll
size: 4,096 bytes 

c:\WINDOWS\system32\TcServices.exe
size: 4,608 bytes 

port: 65 TCP

startup:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "TCShellv1.0"
data: C:\WINDOWS\System32\TcServices.exe 


tested on Windows XP
January 07, 2005

MegaSecurity